

Free tool
ISO 27001 Annex A controls, in plain English
All 93 ISO 27001:2022 Annex A controls, searchable, with what an auditor actually looks for, plus a Statement of Applicability builder.
Every list of the 93 Annex A controls online is a compliance vendor's blog post whose real product is a demo booking, and the thing everyone actually needs, the Statement of Applicability, is behind a form. This is the list, searchable and filterable, with an original plain-English note on each control describing what an assessor asks for and where organisations usually fail. Then it builds your SoA, in your browser, and hands you the file.
Nothing leaves your browser: Your applicability decisions are saved in this browser's local storage so your work survives a refresh, and they are sent nowhere. They do persist on this device until you clear them, and anyone using this browser profile can read them, so treat a shared machine accordingly. An SoA records exactly which controls you have excluded and why, which is sensitive by definition, so this page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon. Open your developer tools and watch the network tab while you work. A policy inside the page cannot stop you copying the result somewhere else, so what you do with it afterwards is yours to protect.
Showing 93 of 93 controls
- 5.1
A defined set of security policies exists, is approved at the right level, is communicated to the people it binds, and is reviewed on a schedule.
- 5.2
Security responsibilities are allocated to named roles, and the people holding them know what they own.
- 5.3
Conflicting duties are separated so no single person can both perform and conceal a damaging action.
- 5.4
Management actively requires staff to apply security in the way the organisation has defined.
- 5.5
Relevant authorities are identified in advance, with named contacts and the circumstances requiring contact.
- 5.6
The organisation maintains contact with security forums and professional bodies so it learns of threats and practice from outside itself.
- 5.7New in 2022
Information about threats is collected and analysed so that it informs the controls the organisation actually operates.
- 5.8
Security requirements are considered within projects, whatever methodology the organisation uses.
- 5.9
An inventory of information and supporting assets exists, with an owner for each.
- 5.10
Rules for acceptable use are defined, communicated, and accepted by the people they apply to.
- 5.11
Assets are returned when employment or a contract ends.
- 5.12
Information is classified according to its sensitivity and to legal and business requirements.
- 5.13
Information carries labels reflecting its classification, in line with the scheme adopted.
- 5.14
Rules and agreements govern transfers of information inside the organisation and to external parties.
- 5.15
Rules controlling physical and logical access are established on business and security requirements.
- 5.16
The full life cycle of identities is managed, from creation to removal.
- 5.17
Allocation and management of authentication information is controlled, including guidance to users.
- 5.18
Access rights are provisioned, reviewed, modified and removed in line with policy.
- 5.19
Processes exist to manage the security risks of using supplier products and services.
- 5.20
Relevant security requirements are established and agreed with each supplier.
- 5.21
Risks associated with the ICT supply chain, including a supplier's own suppliers, are managed.
- 5.22
Supplier service delivery is monitored and reviewed, and changes to it are managed.
- 5.23New in 2022
Acquisition, use, management and exit of cloud services are governed by defined security requirements.
- 5.24
The organisation plans and prepares for incident management, with defined processes, roles and responsibilities.
- 5.25
Events are assessed and a decision is taken on whether each is an incident.
- 5.26
Incidents are responded to in accordance with documented procedures.
- 5.27
Knowledge from incidents is used to strengthen controls.
- 5.28
Procedures exist for identifying, collecting and preserving evidence relating to incidents.
- 5.29
Security is maintained at an appropriate level during disruption, rather than suspended to restore service.
- 5.30New in 2022
ICT readiness is planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements.
- 5.31
Applicable legal and contractual requirements are identified, documented and kept current.
- 5.32
Procedures protect intellectual property rights, including licensing compliance.
- 5.33
Records are protected from loss, destruction, falsification, unauthorised access and unauthorised release.
- 5.34
Privacy requirements are identified and met in line with applicable law and contracts.
- 5.35
The approach to managing information security is reviewed independently at planned intervals and on significant change.
- 5.36
Compliance with the organisation's own security policies and standards is regularly reviewed.
- 5.37
Operating procedures for information processing facilities are documented and available to those who need them.
- 6.1
Background verification is carried out before employment, proportionate to the sensitivity of the role.
- 6.2
Employment agreements state the security responsibilities of the individual and the organisation.
- 6.3
Staff receive appropriate awareness, education and training, updated as policy and threat change.
- 6.4
A formalised, communicated process exists for acting on security policy violations.
- 6.5
Security responsibilities that remain valid after employment ends or changes are defined and enforced.
- 6.6
Confidentiality agreements reflecting the organisation's needs are identified, documented, reviewed and signed.
- 6.7
Security measures are applied when staff work remotely.
- 6.8
Staff can report observed or suspected security events through appropriate channels, in a timely way.
- 7.1
Perimeters are defined and used to protect areas containing information and other associated assets.
- 7.2
Secure areas are protected by appropriate entry controls and access points.
- 7.3
Physical security for offices, rooms and facilities is designed and applied.
- 7.4New in 2022
Premises are continuously monitored for unauthorised physical access.
- 7.5
Protection is designed against physical and environmental threats such as fire, flood and natural hazards.
- 7.6
Security measures for working in secure areas are designed and applied.
- 7.7
Clear desk rules for papers and removable media, and clear screen rules for processing facilities, are defined and applied.
- 7.8
Equipment is sited securely and protected.
- 7.9
Assets used away from the organisation's premises are protected.
- 7.10
Storage media are managed through acquisition, use, transport and disposal in line with classification and handling requirements.
- 7.11
Facilities are protected from power failures and other disruption caused by failures of supporting utilities.
- 7.12
Cabling carrying power, data or supporting services is protected from interception, interference and damage.
- 7.13
Equipment is maintained correctly to ensure availability, integrity and confidentiality of information.
- 7.14
Equipment containing storage media is verified to ensure sensitive data and licensed software are removed or securely overwritten before disposal or re-use.
- 8.1
Information stored on, processed by or accessible via user endpoint devices is protected.
- 8.2
The allocation and use of privileged access rights is restricted and managed.
- 8.3
Access to information and other associated assets is restricted in accordance with the access control policy.
- 8.4
Read and write access to source code, development tools and software libraries is appropriately managed.
- 8.5
Secure authentication technologies and procedures are implemented based on access restrictions and the access control policy.
- 8.6
Use of resources is monitored and adjusted in line with current and expected capacity requirements.
- 8.7
Protection against malware is implemented and supported by appropriate user awareness.
- 8.8
Information about technical vulnerabilities is obtained, exposure evaluated, and appropriate measures taken.
- 8.9New in 2022
Configurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.
- 8.10New in 2022
Information stored in systems, devices or other storage media is deleted when no longer required.
- 8.11New in 2022
Data masking is used in line with the access control policy and business requirements, taking applicable legislation into account.
- 8.12New in 2022
Measures are applied to systems, networks and devices to prevent unauthorised disclosure and extraction of information.
- 8.13
Backup copies of information, software and systems are maintained and regularly tested in line with an agreed policy.
- 8.14
Information processing facilities are implemented with sufficient redundancy to meet availability requirements.
- 8.15
Logs recording activities, exceptions, faults and other relevant events are produced, stored, protected and analysed.
- 8.16New in 2022
Networks, systems and applications are monitored for anomalous behaviour and appropriate action taken to evaluate potential incidents.
- 8.17
Clocks of information processing systems are synchronised to approved time sources.
- 8.18
Use of utility programs capable of overriding system and application controls is restricted and tightly controlled.
- 8.19
Procedures and measures are implemented to securely manage software installation on operational systems.
- 8.20
Networks and network devices are secured, managed and controlled to protect information in systems and applications.
- 8.21
Security mechanisms, service levels and requirements of network services are identified, implemented and monitored.
- 8.22
Groups of information services, users and systems are segregated in networks.
- 8.23New in 2022
Access to external websites is managed to reduce exposure to malicious content.
- 8.24
Rules for effective use of cryptography, including key management, are defined and implemented.
- 8.25
Rules for the secure development of software and systems are established and applied.
- 8.26
Security requirements are identified, specified and approved when developing or acquiring applications.
- 8.27
Principles for engineering secure systems are established, documented, maintained and applied.
- 8.28New in 2022
Secure coding principles are applied to software development.
- 8.29
Security testing processes are defined and implemented in the development life cycle.
- 8.30
Outsourced system development is directed, monitored and reviewed.
- 8.31
Development, testing and production environments are separated and secured.
- 8.32
Changes to information processing facilities and systems are subject to change management procedures.
- 8.33
Test information is appropriately selected, protected and managed.
- 8.34
Audit tests and other assurance activities involving operational systems are planned and agreed to minimise disruption.
All 93 controls
Each control has its own page covering what an assessor looks for, where organisations usually fail, and how it maps back to the 2013 version. 11 controls were introduced in the 2022 revision and are marked.
A.5 Organisational 37 controls
- 5.1Policies for information securityA defined set of security policies exists, is approved at the right level, is communicated to the people it binds, and is reviewed on a schedule.
- 5.2Information security roles and responsibilitiesSecurity responsibilities are allocated to named roles, and the people holding them know what they own.
- 5.3Segregation of dutiesConflicting duties are separated so no single person can both perform and conceal a damaging action.
- 5.4Management responsibilitiesManagement actively requires staff to apply security in the way the organisation has defined.
- 5.5Contact with authoritiesRelevant authorities are identified in advance, with named contacts and the circumstances requiring contact.
- 5.6Contact with special interest groupsThe organisation maintains contact with security forums and professional bodies so it learns of threats and practice from outside itself.
- 5.7Threat intelligenceNewInformation about threats is collected and analysed so that it informs the controls the organisation actually operates.
- 5.8Information security in project managementSecurity requirements are considered within projects, whatever methodology the organisation uses.
- 5.9Inventory of information and other associated assetsAn inventory of information and supporting assets exists, with an owner for each.
- 5.10Acceptable use of information and other associated assetsRules for acceptable use are defined, communicated, and accepted by the people they apply to.
- 5.11Return of assetsAssets are returned when employment or a contract ends.
- 5.12Classification of informationInformation is classified according to its sensitivity and to legal and business requirements.
- 5.13Labelling of informationInformation carries labels reflecting its classification, in line with the scheme adopted.
- 5.14Information transferRules and agreements govern transfers of information inside the organisation and to external parties.
- 5.15Access controlRules controlling physical and logical access are established on business and security requirements.
- 5.16Identity managementThe full life cycle of identities is managed, from creation to removal.
- 5.17Authentication informationAllocation and management of authentication information is controlled, including guidance to users.
- 5.18Access rightsAccess rights are provisioned, reviewed, modified and removed in line with policy.
- 5.19Information security in supplier relationshipsProcesses exist to manage the security risks of using supplier products and services.
- 5.20Addressing information security within supplier agreementsRelevant security requirements are established and agreed with each supplier.
- 5.21Managing information security in the ICT supply chainRisks associated with the ICT supply chain, including a supplier's own suppliers, are managed.
- 5.22Monitoring, review and change management of supplier servicesSupplier service delivery is monitored and reviewed, and changes to it are managed.
- 5.23Information security for use of cloud servicesNewAcquisition, use, management and exit of cloud services are governed by defined security requirements.
- 5.24Information security incident management planning and preparationThe organisation plans and prepares for incident management, with defined processes, roles and responsibilities.
- 5.25Assessment and decision on information security eventsEvents are assessed and a decision is taken on whether each is an incident.
- 5.26Response to information security incidentsIncidents are responded to in accordance with documented procedures.
- 5.27Learning from information security incidentsKnowledge from incidents is used to strengthen controls.
- 5.28Collection of evidenceProcedures exist for identifying, collecting and preserving evidence relating to incidents.
- 5.29Information security during disruptionSecurity is maintained at an appropriate level during disruption, rather than suspended to restore service.
- 5.30ICT readiness for business continuityNewICT readiness is planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements.
- 5.31Legal, statutory, regulatory and contractual requirementsApplicable legal and contractual requirements are identified, documented and kept current.
- 5.32Intellectual property rightsProcedures protect intellectual property rights, including licensing compliance.
- 5.33Protection of recordsRecords are protected from loss, destruction, falsification, unauthorised access and unauthorised release.
- 5.34Privacy and protection of personally identifiable informationPrivacy requirements are identified and met in line with applicable law and contracts.
- 5.35Independent review of information securityThe approach to managing information security is reviewed independently at planned intervals and on significant change.
- 5.36Compliance with policies, rules and standards for information securityCompliance with the organisation's own security policies and standards is regularly reviewed.
- 5.37Documented operating proceduresOperating procedures for information processing facilities are documented and available to those who need them.
A.6 People 8 controls
- 6.1ScreeningBackground verification is carried out before employment, proportionate to the sensitivity of the role.
- 6.2Terms and conditions of employmentEmployment agreements state the security responsibilities of the individual and the organisation.
- 6.3Information security awareness, education and trainingStaff receive appropriate awareness, education and training, updated as policy and threat change.
- 6.4Disciplinary processA formalised, communicated process exists for acting on security policy violations.
- 6.5Responsibilities after termination or change of employmentSecurity responsibilities that remain valid after employment ends or changes are defined and enforced.
- 6.6Confidentiality or non-disclosure agreementsConfidentiality agreements reflecting the organisation's needs are identified, documented, reviewed and signed.
- 6.7Remote workingSecurity measures are applied when staff work remotely.
- 6.8Information security event reportingStaff can report observed or suspected security events through appropriate channels, in a timely way.
A.7 Physical 14 controls
- 7.1Physical security perimetersPerimeters are defined and used to protect areas containing information and other associated assets.
- 7.2Physical entrySecure areas are protected by appropriate entry controls and access points.
- 7.3Securing offices, rooms and facilitiesPhysical security for offices, rooms and facilities is designed and applied.
- 7.4Physical security monitoringNewPremises are continuously monitored for unauthorised physical access.
- 7.5Protecting against physical and environmental threatsProtection is designed against physical and environmental threats such as fire, flood and natural hazards.
- 7.6Working in secure areasSecurity measures for working in secure areas are designed and applied.
- 7.7Clear desk and clear screenClear desk rules for papers and removable media, and clear screen rules for processing facilities, are defined and applied.
- 7.8Equipment siting and protectionEquipment is sited securely and protected.
- 7.9Security of assets off-premisesAssets used away from the organisation's premises are protected.
- 7.10Storage mediaStorage media are managed through acquisition, use, transport and disposal in line with classification and handling requirements.
- 7.11Supporting utilitiesFacilities are protected from power failures and other disruption caused by failures of supporting utilities.
- 7.12Cabling securityCabling carrying power, data or supporting services is protected from interception, interference and damage.
- 7.13Equipment maintenanceEquipment is maintained correctly to ensure availability, integrity and confidentiality of information.
- 7.14Secure disposal or re-use of equipmentEquipment containing storage media is verified to ensure sensitive data and licensed software are removed or securely overwritten before disposal or re-use.
A.8 Technological 34 controls
- 8.1User endpoint devicesInformation stored on, processed by or accessible via user endpoint devices is protected.
- 8.2Privileged access rightsThe allocation and use of privileged access rights is restricted and managed.
- 8.3Information access restrictionAccess to information and other associated assets is restricted in accordance with the access control policy.
- 8.4Access to source codeRead and write access to source code, development tools and software libraries is appropriately managed.
- 8.5Secure authenticationSecure authentication technologies and procedures are implemented based on access restrictions and the access control policy.
- 8.6Capacity managementUse of resources is monitored and adjusted in line with current and expected capacity requirements.
- 8.7Protection against malwareProtection against malware is implemented and supported by appropriate user awareness.
- 8.8Management of technical vulnerabilitiesInformation about technical vulnerabilities is obtained, exposure evaluated, and appropriate measures taken.
- 8.9Configuration managementNewConfigurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.
- 8.10Information deletionNewInformation stored in systems, devices or other storage media is deleted when no longer required.
- 8.11Data maskingNewData masking is used in line with the access control policy and business requirements, taking applicable legislation into account.
- 8.12Data leakage preventionNewMeasures are applied to systems, networks and devices to prevent unauthorised disclosure and extraction of information.
- 8.13Information backupBackup copies of information, software and systems are maintained and regularly tested in line with an agreed policy.
- 8.14Redundancy of information processing facilitiesInformation processing facilities are implemented with sufficient redundancy to meet availability requirements.
- 8.15LoggingLogs recording activities, exceptions, faults and other relevant events are produced, stored, protected and analysed.
- 8.16Monitoring activitiesNewNetworks, systems and applications are monitored for anomalous behaviour and appropriate action taken to evaluate potential incidents.
- 8.17Clock synchronisationClocks of information processing systems are synchronised to approved time sources.
- 8.18Use of privileged utility programsUse of utility programs capable of overriding system and application controls is restricted and tightly controlled.
- 8.19Installation of software on operational systemsProcedures and measures are implemented to securely manage software installation on operational systems.
- 8.20Networks securityNetworks and network devices are secured, managed and controlled to protect information in systems and applications.
- 8.21Security of network servicesSecurity mechanisms, service levels and requirements of network services are identified, implemented and monitored.
- 8.22Segregation of networksGroups of information services, users and systems are segregated in networks.
- 8.23Web filteringNewAccess to external websites is managed to reduce exposure to malicious content.
- 8.24Use of cryptographyRules for effective use of cryptography, including key management, are defined and implemented.
- 8.25Secure development life cycleRules for the secure development of software and systems are established and applied.
- 8.26Application security requirementsSecurity requirements are identified, specified and approved when developing or acquiring applications.
- 8.27Secure system architecture and engineering principlesPrinciples for engineering secure systems are established, documented, maintained and applied.
- 8.28Secure codingNewSecure coding principles are applied to software development.
- 8.29Security testing in development and acceptanceSecurity testing processes are defined and implemented in the development life cycle.
- 8.30Outsourced developmentOutsourced system development is directed, monitored and reviewed.
- 8.31Separation of development, test and production environmentsDevelopment, testing and production environments are separated and secured.
- 8.32Change managementChanges to information processing facilities and systems are subject to change management procedures.
- 8.33Test informationTest information is appropriately selected, protected and managed.
- 8.34Protection of information systems during audit testingAudit tests and other assurance activities involving operational systems are planned and agreed to minimise disruption.
Use the data
All 93 controls are published as JSON under CC BY 4.0, currently version 1.0.0, including the 2013 mapping and our classification. Map it into your own tooling or build something better on it.
What this reproduces, and what it does not
ISO and BSI hold copyright in the text of the standard. Control numbers and short titles are identifiers, used across the industry as references, and are used that way here. No text from ISO/IEC 27001 or 27002 is reproduced. Every intent, assessor note and common finding on this site is original writing, and the type and property classifications are our own analysis aligned to the shape of the ISO 27002 attribute model rather than a copy of its tables.
If you are implementing the standard you need to buy it, and you should. This is a companion to the normative text, not a replacement for it, and no free resource can be otherwise.
Common questions
›How many controls are in ISO 27001:2022 Annex A?
93, reorganised into four themes: 37 organisational (A.5), 8 people (A.6), 14 physical (A.7) and 34 technological (A.8). The 2013 version had 114 controls across 14 domains. The count fell because controls were merged rather than removed, and 11 genuinely new ones were added.
›Which controls are new in the 2022 version?
Eleven: threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28). Filter by 'New in 2022' to read them together.
›What is a Statement of Applicability?
The document recording, for every one of the 93 controls, whether it applies to your management system, the justification for that decision, and its implementation status. It is the single most scrutinised artefact in a certification audit, because it is where an auditor checks that your control set actually follows from your risk assessment.
›Can I exclude controls from my SoA?
Yes, and you will. What you cannot do is exclude one without a justification an auditor accepts, and 'we do not do that' is rarely sufficient on its own. The justification should trace back to your scope and your risk assessment. This tool flags any exclusion you leave unjustified, because every one of them will be raised.
›Does this reproduce the text of the standard?
No, deliberately. ISO and BSI hold copyright in the standard's text. Control numbers and short titles are identifiers and are used here as references, but every explanatory note is original writing about what assessors look for in practice. You still need to buy ISO/IEC 27001 and 27002, and you should: this is a companion to the standard, not a substitute for it.
›Is the exported file a certifiable SoA?
It is a working document, not a finished one. A certifiable SoA has to sit on top of a documented risk assessment and risk treatment plan, and be approved through your management system. What this gives you is the structure, the decisions and the justifications in a file you can take into that process rather than starting from a blank spreadsheet.
When you need more than a tool
ISO/IEC 27001 Implementation and Remediation
Full-cycle ISO/IEC 27001 consultancy: gap analysis, ISMS implementation, remediation of failed audits, and internal audit cycles, led by a Lead Auditor with six programmes taken through certification.
Plan your certification
